detection model
- North America > United States (0.04)
- Europe > Germany > Baden-Württemberg > Tübingen Region > Tübingen (0.04)
- Caspian Sea (0.04)
- (3 more...)
- Energy (0.49)
- Transportation (0.46)
Appendix 545 A Details of datasets and architectures 546 A.1 Object Detection Image Dataset
We evaluate our method on three well-known model architectures:, i.e., SSD [ Named Entity Recognition, and Question Answering. Find more details in Table 5. Recall, ROC-AUC, and Average Scanning Overheads for each model. A value of 1 indicates perfect classification, while a value of 0.5 indicates To the best of our knowledge, there is no existing detection methods for object detection models. We evaluate the IoU threshold used to calculate the ASR of inverted triggers. However, a threshold of 0.7 tends to degrade the Different score thresholds are tested when computing the ASR of inverted triggers.
- North America > United States > Indiana > Tippecanoe County > West Lafayette (0.05)
- North America > United States > Indiana > Tippecanoe County > Lafayette (0.05)
- Asia > Nepal (0.04)
- (5 more...)
- Research Report > Experimental Study (0.93)
- Research Report > New Finding (0.67)
- Information Technology (0.68)
- Education (0.46)
- Information Technology > Artificial Intelligence > Vision (1.00)
- Information Technology > Artificial Intelligence > Representation & Reasoning (1.00)
- Information Technology > Artificial Intelligence > Natural Language (1.00)
- Information Technology > Artificial Intelligence > Machine Learning > Neural Networks > Deep Learning (0.46)
- South America > Brazil (0.04)
- Asia > Middle East > Israel (0.04)
- North America > United States > California > Santa Clara County > Palo Alto (0.04)
- North America > Canada > British Columbia > Metro Vancouver Regional District > Vancouver (0.04)
- Europe > United Kingdom > Wales > Ceredigion (0.04)
- Asia > China > Shaanxi Province > Xi'an (0.04)
- Information Technology (0.46)
- Transportation > Ground > Road (0.31)
- Automobiles & Trucks (0.31)
- North America > United States > California > Santa Clara County > Palo Alto (0.15)
- North America > United States > Wisconsin > Winnebago County > Oshkosh (0.04)
- North America > United States > Nevada > Washoe County > Reno (0.04)
- North America > United States > Massachusetts > Suffolk County > Boston (0.04)
- Transportation > Air (1.00)
- Aerospace & Defense > Aircraft (1.00)
- Government (0.70)
- Information Technology > Artificial Intelligence > Vision (1.00)
- Information Technology > Artificial Intelligence > Robots > Autonomous Vehicles (1.00)
- Information Technology > Artificial Intelligence > Representation & Reasoning (1.00)
- Information Technology > Artificial Intelligence > Machine Learning > Neural Networks > Deep Learning (0.46)
BlackboxAttacksviaSurrogateEnsembleSearch SupplementaryMaterial Summary
Some previous papers (e.g., MIM [7])claimedthat ensemble with weighted logits (equation (4) in main text) outperforms ensemble with weighted probabilities and weighted combination of loss (equations(3)and(5)in main text). In our experiments, shown in Figure 6b, we observe that weighted combination of surrogate loss functions provide similar or even higher fooling rate compared to weighted probabilities or logits.